Version 2.0 · Last updated: 7 August 2026 · Replaces the version of 27 July 2025
In short. DLV Insight is a profit-analytics tool for Amazon sellers. We process your business data solely to run the Service for you. We do not sell, rent, share or monetise your data, and we do not use it to train machine-learning models or to build any product other than your own dashboards.
We use no advertising trackers, no third-party web analytics, and no social-media plugins on the application. The only cookies we set are those strictly necessary to keep you signed in.
The controller responsible for the processing described in this Policy is:
| Company | DLV Insight OÜ |
|---|---|
| Registered address | Ruunaoja tn 3, Lasnamäe linnaosa, 11415 Tallinn, Harju maakond, Estonia |
| Registry code | 17299306 |
| Country of establishment | Estonia (European Union) |
| Privacy contact | privacy@dlvinsight.com |
| General support | support@dlvinsight.com |
| Lead supervisory authority | Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), Tatari 39, 10134 Tallinn, Estonia — www.aki.ee |
We are not required to appoint a Data Protection Officer under Article 37 GDPR, and we have not appointed one. Privacy matters are handled directly by our management at the address above.
This Policy covers the DLV Insight web application at app.dlvinsight.com, our public website, and our related services (together, the "Service").
We handle two different kinds of personal data in two different legal roles. The distinction matters, because it determines who you should contact about what.
| Role | Data | What it means |
|---|---|---|
| We are the controller | Data about you, our customer: your account, your colleagues' accounts, billing data, support correspondence, and technical logs. | We decide why and how this data is processed. Address requests about it to us directly (section 11). |
| We are a processor | Data inside your connected sales channels that relates to your end customers — principally buyer contact and delivery data received from Amazon and other connected platforms. | You are the controller. We process it only on your documented instructions, under a Data Processing Agreement. Requests from your end customers go to you, not to us (section 12). |
Our Data Processing Agreement, which forms part of our Terms of Service, governs the processor relationship and satisfies Article 28(3) GDPR. It is available at /static/saas_dpa.html.
The substance of the Service. Retrieved from the sales channels you choose to connect:
Most of this is commercial data about products and money, not about people. Where individual records do relate to an identifiable buyer, section 5 applies.
Order records received from connected platforms may contain buyer identifiers and delivery details. See section 5 for exactly what we do with these, how quickly we remove them, and why.
OAuth refresh tokens and API credentials for the channels you connect (Amazon Selling Partner API, Amazon Advertising, QuickBooks, BaseLinker and similar). These are encrypted at the application layer with AES-256-GCM before being written to the database, and the encryption key is held in a managed secret store, never in our source code.
Server logs recording IP address, timestamp, requested URL, response status, user agent and error diagnostics. Used for security, abuse prevention and troubleshooting. We do not use this data to profile you, and we do not combine it with your business data for any analytical purpose.
Where we act as controller, we rely on the following bases under Article 6(1) GDPR:
| Processing | Legal basis | Notes |
|---|---|---|
| Creating and running your account; delivering the analytics you subscribed to | Contract — Art. 6(1)(b) | Without this data we cannot provide the Service. |
| Billing, invoicing, dunning | Contract — Art. 6(1)(b) | |
| Retaining accounting records | Legal obligation — Art. 6(1)(c) | Estonian Accounting Act; seven-year retention. |
| Service emails (security notices, billing, material changes) | Contract — Art. 6(1)(b) | These are not marketing and cannot be unsubscribed from while your account is active. |
| Security, abuse prevention, log retention, backups | Legitimate interests — Art. 6(1)(f) | Our interest: keeping the Service and your data secure. Balanced against your rights; the data involved is minimal and never used for profiling. |
| Defending or bringing legal claims | Legitimate interests — Art. 6(1)(f) | |
| Marketing emails, where offered | Consent — Art. 6(1)(a) | Opt-in only, withdrawable at any time, with an unsubscribe link in every message. |
You may object at any time to processing based on legitimate interests, on grounds relating to your particular situation (section 11).
When you connect an Amazon seller account, you authorise us to retrieve data through Amazon's Selling Partner API on your behalf. This processing is additionally governed by Amazon's Data Protection Policy and Acceptable Use Policy, which we are contractually bound to follow.
Some Amazon reports contain buyer personal information — for example a buyer email address, name, telephone number, or delivery and billing address. We apply the following controls:
We use buyer personal information solely for the purposes Amazon permits: fulfilling and reconciling orders, tax calculation, remittance and invoicing, and compliance with legal obligations. We do not use it for advertising, for enrichment, for resale, or for any purpose outside the Service you have subscribed to.
Amazon and other platform providers may audit our handling of data obtained through their APIs. We may be required to provide evidence of compliance, and access to a connected channel may be suspended while an audit is in progress. We will tell you promptly if that affects your account.
We use the data described above only to:
We do not: sell, rent or trade personal data; share your business data with other customers; use your data to train machine-learning or AI models; use it for advertising; or benchmark your business against others in any way that identifies you.
We keep our supplier list deliberately short. The following are the only third parties that process personal data on our behalf:
| Sub-processor | Purpose | Data | Location & safeguard |
|---|---|---|---|
| Google Cloud (Google Cloud EMEA Ltd, Ireland) |
Application hosting, database, file storage, secret management, logging | All categories | Stored in the EU (europe-west1, Belgium). EU entity; Standard Contractual Clauses cover any support access from outside the EEA. |
| Clerk (Clerk.com Inc., USA) |
Authentication, session and organisation management | Name, email, password hash, MFA secrets, sign-in IP and timestamps | USA. Standard Contractual Clauses under Art. 46(2)(c) GDPR, with supplementary technical measures. |
| Stripe (Stripe Payments Europe Ltd, Ireland) |
Subscription billing and payment processing | Name, email, billing address, VAT number, payment method (held by Stripe, not by us) | EU entity, with onward transfer to Stripe, Inc. (USA) under Standard Contractual Clauses. Stripe is an independent controller for fraud prevention and regulatory purposes. |
An up-to-date list is maintained at this section of this page. We will give customers at least 30 days' notice before adding or replacing a sub-processor, during which you may object on reasonable data-protection grounds, as set out in the Data Processing Agreement.
When you connect Amazon, Amazon Advertising, QuickBooks, BaseLinker or a similar platform, data flows between that platform and DLV Insight at your instruction. Those platforms are independent controllers for their own processing, governed by their own terms and privacy notices. Disconnecting a channel at any time stops the flow.
We may disclose personal data where we are legally required to, or to establish, exercise or defend legal claims. If we are compelled to disclose data relating to your account, we will notify you unless legally prohibited from doing so. In the event of a merger, acquisition or asset sale, data may transfer to the acquirer, who will remain bound by this Policy; we will notify you before any such transfer takes effect.
Your business data — orders, financial transactions, products, advertising and all derived analytics — is stored and processed within the European Union, in Google Cloud's europe-west1 region in Belgium. It is not replicated outside the EU.
Two categories leave the EU, each covered by an Article 46 transfer mechanism: authentication data processed by Clerk in the United States, and payment data processed by Stripe, which may transfer to the United States. Both transfers rely on the European Commission's Standard Contractual Clauses, supplemented by encryption in transit and at rest and by contractual limits on government-access requests. You may request a copy of the relevant clauses by writing to privacy@dlvinsight.com.
| Data | Retention period | Basis |
|---|---|---|
| Account and organisation data | Duration of the subscription, then 90 days | Grace period for reactivation and export. Deleted after. |
| Seller business data (orders, finance, products, ads) | Duration of the subscription, then 90 days | Deleted on request at any time, or immediately on request after termination. |
| Buyer plaintext identifiers (email, name, telephone) | Maximum 30 days after order delivery | Amazon Data Protection Policy; GDPR storage limitation. |
| Buyer delivery street address and postal code | Maximum 30 days after order delivery | Reduced to region or country thereafter. |
| Pseudonymous buyer identifier | Duration of the subscription | Irreversible keyed hash; required for repeat-purchase and lifetime-value analytics. |
| Accounting and invoice records | 7 years | Estonian Accounting Act. Cannot be deleted on request. |
| Server and security logs | Up to 90 days | Security and troubleshooting. |
| Support correspondence | 3 years from last contact | Service quality and legal claims. |
| Backups | Rolling, up to 35 days | Deletions propagate to backups as those backups expire on their normal cycle. |
You may export your data at any time while your subscription is active. On termination we retain your data for 90 days so you can reactivate or export, and then delete it. If you want it deleted sooner, write to us and we will do so within 30 days, except for records we are legally required to keep.
We implement appropriate technical and organisational measures under Article 32 GDPR. The measures actually in place are:
No system can be guaranteed absolutely secure. These measures reflect the state of the art proportionate to the risk, and we review them as the Service evolves. Nothing in this section limits your rights or our liability under Article 82 GDPR.
Where we act as controller, you have the following rights under the GDPR:
Write to privacy@dlvinsight.com. We respond within one month of receipt. Where a request is complex or you have made several, we may extend this by up to two further months, and we will tell you within the first month if we do, along with the reasons.
Exercising these rights is free of charge. We will only charge a reasonable fee, or refuse to act, where a request is manifestly unfounded or excessive — in particular because of its repetitive character — and the burden of demonstrating that rests with us. If we refuse, we will tell you why, and inform you of your right to complain to a supervisory authority and to seek a judicial remedy.
We may ask for information reasonably necessary to confirm your identity where we have genuine doubts about it. We will not use an identity check to delay a legitimate request.
If you are a buyer who purchased from a seller using DLV Insight: we process your data only as a processor, on that seller's instruction. Please direct your request to the seller, who is the controller. If you contact us directly, we will forward your request to the relevant seller without undue delay and tell you that we have done so, unless we are instructed or legally required to act otherwise.
Where a customer instructs us to give effect to an access, erasure or restriction request, we act on that instruction without undue delay, as required by the Data Processing Agreement.
We use strictly necessary cookies only. The application sets no advertising cookies, no third-party analytics cookies and no social-media plugins. We have not integrated Google Analytics, Meta, or any comparable tracking service.
| Cookie | Purpose | Duration |
|---|---|---|
| Clerk session cookies | Keeps you signed in and protects against cross-site request forgery | Session and short-lived refresh |
| Language preference | Remembers your chosen interface language | Up to 12 months |
| Theme preference | Remembers light or dark appearance | Up to 12 months |
Because these cookies are strictly necessary to deliver a service you have requested, they fall within the exemption in Article 5(3) of the ePrivacy Directive and do not require consent. That is why you do not see a cookie banner. If we ever introduce a non-essential cookie, we will ask for your consent first, through a banner that lets you refuse as easily as accept, and we will update this section before doing so.
You can block or delete cookies in your browser settings, but the Service will not function without the session cookies, since we would be unable to keep you signed in.
If you are a resident of California, Colorado, Connecticut, Virginia or another US state with comprehensive privacy legislation, this section applies to you in addition to the rest of this Policy.
We do not sell personal information, and we do not share it for cross-context behavioural advertising, as those terms are defined in the California Consumer Privacy Act as amended by the CPRA. We have not done so in the preceding twelve months. Because we do not sell or share, there is no opt-out to offer; we honour Global Privacy Control signals as a matter of course, and nothing in our practices depends on you sending one.
In the preceding twelve months we have collected the following categories of personal information, for the business purposes described in section 6, from the sources in section 3, and disclosed them only to the service providers in section 7:
We do not collect sensitive personal information as defined by the CPRA, and we do not use or disclose it for purposes requiring a right to limit.
You have the right to know, to access, to delete, to correct, and to be free from discrimination for exercising any of these rights. We will not deny you service, charge you a different price, or provide a lesser quality of service because you exercised a privacy right. To make a request, write to privacy@dlvinsight.com. You may use an authorised agent, in which case we will require written proof of authorisation. We respond within 45 days, extendable once by a further 45 days with notice.
We do not carry out automated decision-making that produces legal effects concerning you, or that similarly significantly affects you, within the meaning of Article 22 GDPR. We do not profile you.
The Service does generate automated forecasts and analytics — sales forecasts, safety-stock recommendations, advertising insights — but these are commercial calculations about products and campaigns, presented for you to act on. They make no decisions about individuals.
The Service is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, write to privacy@dlvinsight.com and we will delete it.
Where we act as controller and a breach is likely to result in a risk to your rights and freedoms, we notify the Estonian Data Protection Inspectorate within 72 hours of becoming aware of it, and we notify you without undue delay where the risk is high, as required by Articles 33 and 34 GDPR.
Where we act as processor, we notify you as controller without undue delay after becoming aware of a breach affecting data we process for you, with the information you need to meet your own notification obligations.
We may update this Policy as the Service changes. The version number and date at the top always reflect the current text.
For material changes — a new purpose, a new category of data, a new sub-processor, or a change to retention — we will give you at least 30 days' notice by email to your account address, or by prominent notice in the application, before the change takes effect. Where a change requires your consent under applicable law, we will ask for it rather than assume it.
Privacy questions, rights requests, copies of our Standard Contractual Clauses, or a signed Data Processing Agreement:
DLV Insight OÜ (registry code 17299306)
Ruunaoja tn 3, Lasnamäe linnaosa
11415 Tallinn, Harju maakond
Estonia
privacy@dlvinsight.com
We aim to respond to every privacy enquiry within five working days, and always within the statutory deadlines in section 11.
This Policy is provided for transparency under Articles 13 and 14 GDPR. It is a notice, not a contract, and nothing in it asks you to waive a right or limits our liability under Article 82 GDPR. The contractual terms governing your use of the Service are in our Terms of Service, and the processor terms are in our Data Processing Agreement.